Courseiva
Essential Commands →easyMultiple Choice

LFCS Essential Commands Practice Question

A user wants to view the contents of a compressed log file /var/log/syslog.2.gz without decompressing it first. Which command should they use?

⚠ Common exam trap

Many exam-takers confuse `zcat` with `gunzip` or assume `less` can handle compressed files natively, but the LFCS exam expects knowledge of the specific command designed for viewing compressed files without decompression.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

zcat /var/log/syslog.2.gz

`zcat` is a utility that reads compressed files (typically gzip-compressed) and outputs their decompressed content to standard output without permanently decompressing the file. This allows the user to view the contents of `/var/log/syslog.2.gz` directly in the terminal.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    gunzip /var/log/syslog.2.gz

    Why it's wrong here

    gunzip decompresses the archive in place, replacing syslog.2.gz with an uncompressed file, so it does not view contents without decompressing. It is tempting because gunzip is the standard tool for handling gzip archives, and would be right if the task were to restore the original file.

  • ✗

    cat /var/log/syslog.2.gz

    Why it's wrong here

    cat streams the raw gzip bytes to the terminal, producing binary garbage rather than readable log text. It is tempting as the default file-viewing command, and would be correct for an uncompressed plain-text log such as /var/log/syslog itself.

  • ✓

    zcat /var/log/syslog.2.gz

    Why this is correct

    zcat streams the decompressed contents of gzip-compressed files straight to standard output, leaving the original .gz file untouched on disk. This directly satisfies the stem's constraint of viewing /var/log/syslog.2.gz without decompressing it first, unlike gunzip, which would replace the archive with an uncompressed file.

  • ✗

    less /var/log/syslog.2.gz

    Why it's wrong here

    less reads the gzip stream as raw bytes, displaying compressed binary rather than the log text. It is tempting because less is the usual pager for viewing files, and would be correct for an uncompressed log, but it lacks gzip decompression handling.

About these practice questions

This LFCS question is part of Courseiva's 406-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This LFCS practice question is part of Courseiva's free Linux Foundation certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the LFCS exam.